Vikunja Vulnerable to XSS Via Task Preview
The task preview component creates a unparented div. The div's innerHtml is set to the unescaped description of the task
The task preview component creates a unparented div. The div's innerHtml is set to the unescaped description of the task